External risk intelligence

JoomSport WordPress Plugin Local File Inclusion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-7721

The vulnerability affects a WordPress plugin, which by design powers public-facing web applications. Because the plugin functionality is accessible to unauthenticated users via standard web requests, it is inherently exposed to the public internet in any typical deployment.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the JoomSport WordPress plugin that could allow attackers to execute malicious code on affected servers. This issue impacts the plugin's ability to securely handle file inclusions, potentially leading to unauthorized access to sensitive data or compromise of the server. The main concern is confirming relevance and exposure.

  • Attackers can run code on your server.
  • Affects WordPress sites using this plugin.
  • Confirm if your systems use this plugin.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a crafted request to a vulnerable WordPress site. This request targets a specific feature within the JoomSport plugin, allowing the attacker to trick the system into loading and executing arbitrary PHP files from the server. This capability can lead to serious consequences such as bypassing security measures, accessing sensitive information, or even gaining full control of the server if PHP files can be uploaded and included.

  • No authentication required.
  • Crafted request to a vulnerable plugin feature.
  • Arbitrary PHP file inclusion and execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated attackers could potentially include and execute arbitrary PHP files on a WordPress server. This could lead to the execution of any PHP code, potentially bypassing access controls, accessing sensitive data, or achieving code execution if PHP file uploads are permitted.

  • Server-side PHP files could be at risk.
  • Arbitrary PHP file inclusion and execution.
  • Unauthorized access to sensitive data or code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determining precise ownership requires understanding your WordPress deployment model. Generally, application owners or platform teams manage WordPress instances and their plugins. The initial step is to locate all instances of the JoomSport plugin, assess their external reachability and business criticality, and identify the accountable team for each. Subsequent remediation planning should align with identified risks and operational capacity.

  • Identify plugin and application owners.
  • Verify external reachability and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the JoomSport plugin used for in WordPress?

JoomSport is a WordPress plugin designed to help users manage sports leagues, tournaments, and team results. It adds specialized sports-management features, such as score tracking and scheduling, directly into a WordPress site's framework.

What does Local File Inclusion mean for CVE-2025-7721?

This vulnerability is classified as CWE-98, which involves improper control of file inclusion. Essentially, the plugin fails to sanitize user input, allowing an attacker to trick the system into running files that should not be accessible. This lets unauthorized parties execute arbitrary PHP code on the server hosting the plugin.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted web request to the vulnerable site's 'task' parameter. The attack does not require the user to be logged in or have special permissions. However, the flaw relies on the server's ability to process and include PHP files, meaning the attack is only effective if there is a way to target these specific internal processes.

Is my site at risk according to Halo Surface Signal?

Because this is a WordPress plugin, Halo Surface Signal notes it is designed for public-facing websites and is inherently exposed to the internet. Since the vulnerability allows unauthenticated access via standard web requests, any site running an affected version is considered reachable by external threats.

What are the first steps to handle this CVE?

Start by identifying all instances of the JoomSport plugin within your WordPress infrastructure. Once located, verify which sites are accessible from the internet and evaluate their business importance. Coordinate with your application owners or technical teams to plan necessary updates or security changes based on your specific deployment model.

References